Things That Keep Me Up At Night: Musings On Mortgage Fraud After Two Decades In The Trenches – NMP Skip to main content

Things That Keep Me Up At Night: Musings On Mortgage Fraud After Two Decades In The Trenches

Feb 02, 2026
Keep Me Up At Night–Musings On Mortgage Fraud
President and CEO

Rising wire fraud risks — now amplified by AI-driven deep fakes — are exposing vulnerabilities in mortgage closings and forcing lenders to tighten cybersecurity, employee training, and transaction controls

It is only in the past 10 years or so that banks and mortgage lenders have faced heightened risk from wire fraud losses. In this time period, lenders have been forced to uncover and defend the widespread use of various cyber schemes, including basic phishing, using mass-market emails; spear phishing, using cyber intrusion tactics to go after specific targets; whaling, using email schemes to target key owners and managers (C-level employees); or business email compromise (BEC), where intruders pretend to be the CEO or CFO.

More recently the use of artificial intelligence (AI) is being used to create "deep fakes," AI-generated videos, images, or audio recordings that convincingly mimic real people’s faces, voices, or actions, often making it appear as though someone said or did something they never actually did, such as authorize a wire to the wrong recipient.

These schemes all have one purpose: to disrupt operations by gaining access to internal communications and data, with the intention of causing financial harm.

Due to the relatively uncontrolled nature of communications surrounding the closing of mortgage loans, where many different parties come together to close a transaction, the ability of cyber criminals to infiltrate and cause havoc is a continued threat. It is very difficult for lenders to manage the security of information and data being transferred among so many varied parties: the borrower, seller's attorney, settlement agent, real estate agent, and others, such as property inspectors and appraisers.

Best practices, which are required by financial regulators and by some state data privacy and security statutes (i.e. New York and California come to mind) should include:

  • Ensuring all employees use encrypted email tools when transmitting confidential borrower and transaction data;
  • Prohibiting employees (many of whom are not working from home) from using personal emails and from storing lender and borrower data and documents on unprotected local servers;
  • Requiring sterile home work environments, protecting sensitive consumer and financial information from the prying eyes of anyone without a need to access such information, including family members, neighbors, and guests;
  • Training employees on identifying email phishing schemes, especially whaling schemes, so that they do not inadvertently allow bad actors in through the "front door;"
  • Educating consumers about phishing schemes and how they may impact their transaction, especially through attacks on their personal email accounts;
  • Insisting that all transaction partners verify any wire instructions and adopt a red flag policy whenever wire instructions change abruptly in the midst of a transaction;
  • Adopting password protection policies that require all employees to change access passwords to all systems on a regular basis;
  • Educating staff about "deep fakes" and the deceptive use of AI to create a false impression of an approved yet harmful business decision;
  • Conducting (or outsourcing) system security checks, including penetration checks to expose any weaknesses and vulnerabilities in your technology systems; and
  • Employing a robust vendor management risk assessment and monitoring program to make sure that outsiders whom you allow to access your consumer and financial data (a) are who they say they are, (b) are low risk actors, (c) employ their own internal controls managing their employees and systems, and where they are receiving proceeds (d) have verified trust accounts.

If you are like me, the idea of mortgage fraud keeps me up at night. Check back here each month to learn more about my restless nights.

About the author
President and CEO
Andrew Liput is President and CEO of Hamilton, New Jersey-based Secure Insight, a provider of risk management and wire fraud prevention tools. He may be reached at [email protected].
Published
Feb 02, 2026
ServiceMac Rebrands After Subservicing Portfolio Climbs To $350.8 Billion

The First American subsidiary is sharpening its lender-facing identity after becoming the nation’s fourth-largest mortgage subservicer

Sep 10, 2026
ISS Backs Better Board In Fight With Vishal Garg

The proxy adviser says Garg has not made the case for removing five directors, while Better’s interim CEO outlines a narrower strategy built around wholesale, home equity, and repeatable partnerships

Sep 09, 2026
AngelAi Lands $100 Million To Scale Mortgage Automation

Celligence says the debt financing will support a broader rollout of technology it claims can reduce internal mortgage manufacturing costs to less than $125 per loan

Sep 09, 2026
NEXA Names Geri Farr CEO As Kortas Shifts Focus To Growth Strategy

Farr takes over day-to-day operations while Kortas focuses on acquisitions, partnerships, new businesses, and LO economics

Sep 08, 2026
Real REMAX Ends Motto Growth, But Franchisees’ Place Remains Unclear

The company will consider mutual exits and honor remaining agreements, but has not explained how Motto offices will coexist with its unified mortgage strategy

Sep 04, 2026
Garg Pitches $2 Billion Better Turnaround; Board Calls Plan ‘Unworkable’

Former CEO targets zero monthly cash burn through higher mortgage volume, AI-driven operating changes, and $2 million in monthly savings

Sep 04, 2026